Microsoft Copilot security directory
Workday
Published by Microsoft
High risk
Use the Workday connector to invoke Workday SOAP and REST services for performing various on-demand business management services.
Security assessment
Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.
- Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
- Can execute code or queries: This connector can run arbitrary queries or code against a database or execution engine. An AI-generated query could be manipulated to exfiltrate, corrupt, or destroy data.
- Stores long-lived access tokens: This connector requires persistent credentials. If those tokens leak or are stolen, whoever holds them gets the same access you granted.
- Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.
Available capabilities
This add-on exposes 11 tools or capabilities.
- Execute RaaS operation
- Execute SOAP operation
- Get feedback templates (Preview)
- Get my worker profile (Preview)
- Get supervisory organizations managed by worker (Preview)
- Get worker direct reports (Preview)
- Get worker inbox tasks (Preview)
- Get worker pay slips (Preview)
- Request feedback on worker (Preview)
- Search workers (Preview)
- Transfer employee (Preview)
The interactive security report will load automatically.